You can enable access controls on any Windows or Linux data disk that has been encrypted by DataControl. Access controls are not supported on Windows boot disks, Linux root or swap disks, or unencrypted data disks.
Before You Begin
If this is a Linux disk:
Procedure
Click the Expand button (>) at the end of the row associated with the VM whose disks you want to protect.
KeyControl displays the details for the VM along with a VM-specific Actions button that allows you to manage the selected VM without affecting other VMs registered with KeyControl.
In the list of disks, click on the data disk that you want to associate with an Access Control Policy and select Actions > Add Policy to Disk from the VM-specific Actions button.
Tip: | If the Add Policy to Disk option is not available for a Linux disk, make sure access controls have been enabled on the VM as described in Enabling Access Controls on a Linux VM. |
In the Available Policies dialog box, select the policy that you want to use and click Add Policy.
At the selected VM's next heartbeat, the HyTrust DataControl Policy Agent attempts to associate the Access Control Policy with the selected disk. At this time, the Policy Agent verifies the permissions specified in the associated policy rules. If all permission entries are valid, the association is successful and access controls are enabled for that disk. The Policy Agent records the successful application of the policy in the Audit Log.
Important: | If any of the permissions list entries are invalid, the Policy Agent issues an alert and does not apply the Access Control Policy. If this is an update to an existing policy, what happens next depends on the type of disk. For Linux disks, the Policy Agent continues to use the previous version of the policy. For Windows disks, the Policy Agent continues to use the previous policy settings until the VM reboots. If the permissions list contains invalid entries when the Windows VM reboots, the Policy Agent disables all access controls for the disk. |
What to Do Next
If you want to force an update so that the Access Control Policy is applied before the next scheduled heartbeat, you can log into the VMs as an administrator and use the hcl heartbeat
command.
Note: | For a Linux disk, the heartbeat command may take a few minutes to complete the first time an Access Control Policy is associated with the disk. If you use this command, make sure you wait for it to complete because interrupting the policy association process may cause issues on the VM. |